My Even DEEPER Dive into Custom DNS Across VPNs...

Поділитися
Вставка
  • Опубліковано 1 чер 2024
  • Let's deep-dive into the recent video I published covering my NextDNS + IVPN configuration - covering mistakes I made, diving deeper into the hole, and directly addressing some of your questions & concerns. Also diving into Windscribe, ProtonVPN, Mullvad, and more.
    Recent video: • FINALLY! The VPN Confi...
    ➡️ NextDNS Kickback Link: nextdns.io/?from=5v4be7mt
    ➡️ NextDNS Standard Link: nextdns.io/
    A few more updates:
    - IVPN updated their documentation to be clearer! www.ivpn.net/knowledgebase/ge...
    - Android is actually using DoT, NOT DoH. Though for the purposes of this video this shouldn't impact the takeaways or general concepts.
    - NextDNS has an open source CLI tool, though their native clients don't appear to be open source. With that said, we're not trying to use the native clients & I'm not concerned with the server being open source since there's no way for us to verify they're running that code anyway. But definitely a correction for people who desire more of these things.
    - Linux & Windows have native DoH options that may work with some of these VPNs. (Didn't test this myself)
    Thank you to people who are sharing more information regarding this situation, as always - I'm learning more from comments on UA-cam than from service's themself, which is really my core complaint here.
    🔐 Our Website: techlore.tech
    🕵 Go Incognito Course - to learn about privacy: techlore.tech/goincognito
    🏫 Techlore Coaching - to get direct support: techlore.tech/coaching
    💻 Techlore Forum - to connect with other advocates: discuss.techlore.tech
    🦣 Mastodon - to stay updated: social.lol/@techlore
    We cannot provide our content without our Patrons, huge thanks to:
    BRIGHTSIDE, Clark, Ente, Larry, Afonso, Boori, Brad, Casper, Cookie, Floyd, JohnnyO, kevin, love your content, NotSure, Poaclu, x
    🧡 Join them on Patreon: / techlore
    💚 To see our production gear, privacy tools we use, and other affiliates: techlore.tech/affiliates
    💖 All Techlore Support Methods: techlore.tech/support
    00:00 Introduction
    00:35 Mistakes
    02:47 Windscribe Demo
    06:43 ProtonVPN Demo
    09:17 Mullvad Demo
    13:03 IVPN Demo
    14:51 Literally just complaining about documentation
    17:44 Directly answering questions and addressing concerns
    #nextDNS #techlore #DNS
  • Наука та технологія

КОМЕНТАРІ • 81

  • @techlore
    @techlore  Рік тому +15

    OKAY hopefully this cleared up a lot of the questions I was getting in our last video :) Thank you all for the feedback!
    Don't forget to check out our Patreon: patreon.com/techlore
    A few more updates:
    - IVPN updated their documentation to be clearer! www.ivpn.net/knowledgebase/general/custom-dns/
    - Android is actually using DoT, NOT DoH. Though for the purposes of this video this shouldn't impact the takeaways or general concepts.
    - NextDNS has an open source CLI tool, though their native clients don't appear to be open source. With that said, we're not trying to use the native clients & I'm not concerned with the server being open source since there's no way for us to verify they're running that code anyway. But definitely a correction for people who desire more of these things.
    - Linux & Windows have native DoH options that *may* work with some of these VPNs. (Didn't test this myself)
    Thank you to people who are sharing more information regarding this situation, as always - I'm learning more from comments on UA-cam than from service's themself, which is really my core complaint here.

  • @SimplyDawn
    @SimplyDawn Рік тому +6

    as someone who is fairly new to the tech security & privacy game my initial response was 🤯 but also thank you. i'm trying to decide on a new VPN as i WAS with WeVPN who recently just...went away. my current top two are iVPN & ProtonVPN but, i'm wondering if i should consider others. i'm still too much of a noob to be confident in my decision. i'm also very, very new to the custom DNS scene having been recently introduced to Quad9. at any rate, i do enjoy your videos & appreciate your honesty. thank you, again.

    • @mephisto--
      @mephisto-- 9 місяців тому

      Stay with iVPN my man, just the best one

  • @glyslay4102
    @glyslay4102 Рік тому +5

    In previous one it was clear what IVPN and Net Guard are incompatible because Android can't run two VPNs at the same time. Thanks for fixing the mistake.

  • @danieru3
    @danieru3 Рік тому +3

    Great follow-up. As always appreciate your thoroughness and openness!

  • @BriantDavis78
    @BriantDavis78 Рік тому +3

    As a free use case, windscribe works but you are correct it's ip4 only. For the machine I'm using it on, it's fine. I don't use ip6 on that machine. I am waiting to upgrade my whole network. Wanting to get a pfsense box. I would like DoH but it's fine for a little coffee shop work machine.

  • @verntechph
    @verntechph 8 місяців тому

    Recently using the iVPN and NextDNS combo. Works well on my end.

  • @jerhuta4995
    @jerhuta4995 Рік тому +1

    Windscribe with NextDNS works for me on android. The problem is, it seems to be leaking the DNS request to the windscribe provided one occasionally. When I checked with dnsleaktest, sure it only shows the provided one, even with the extended test. But when I checked with ipleak it shows the that it hits 2 servers, one being the NextDNS with the majority hit (150 vs 2). I also checked if my NextDNS filter is being applied, and it did.

  • @aceiowmydoraph
    @aceiowmydoraph 4 місяці тому

    I use Proton with NextDNS. I use Linux, Windows and Android. Here is how I managed to have both DoT and VPN. Also I want my devices to report their name to identify queries.
    Android
    NextDNS - DoT
    ProtonVPN - Wireguard
    Windows
    NextDNS - yoga dns
    ProtonVPN - Wireguard
    Linux
    NextDNS - systemd-resolved
    ProtonVPN - Wireguard CLI (I don't know why I can't import using GUI Network manager. Using Debian 12 KDE)
    PS.Downloaded Wireguard configs work for both Android and Windows but not Linux. I mean for Linux you have to select GNU/Linux when downloading. So don't try to create a backup in the GUI app and use those config in Linux. In Linux you need to comment out DNS option in the config otherwise say good bye to the internet at least that is what I experienced.

  • @bradyy0rk
    @bradyy0rk Рік тому +6

    Thanks for the followup video. But I have a question about DoH on Android, where do you set that up? The Private DNS option only allows a direct domain, so that only works with DNS-over-TLS/QUIC and not the DoH url. Is there any other setting I am missing? Or did you group DoT and DoH together? I am using Android 13.

    • @techlore
      @techlore  Рік тому +3

      Thank you yes, DoT is technically what's offered on Android 👌 The URL would be 'yourNextDNSID.dns.nextdns.io' - imporperly grouped it together as DoH in this video. -H

  • @wonderfulumens
    @wonderfulumens Рік тому +2

    Windows 11 does support native private custom DNS integration via HTTPS! Both via IPV4 and IPV6! I'm using Proton VPN with NextDNS comfortably on both Windows and Android without even touching the configuration of the VPN clients.

    • @wildyato3737
      @wildyato3737 7 місяців тому

      Next DNS is a messed up ever don't use ...
      rather than using ControlD

  • @mdlahey3874
    @mdlahey3874 Рік тому +1

    Still a little puzzled: I use ivpn on my Android phone, mostly. I have "custom/private" DNS set to use NextDNS under the Android OS settings. Do I also need to tell the ivpn app to use custom/private DNS, i.e. NextDNS? IOW, one or both? Sorry if dumb question...

    • @turbolag5107
      @turbolag5107 Рік тому

      I did the same with Proton VPN and when I go to DNS checking sites, they all say Next DNS.

  • @jackoneil3933
    @jackoneil3933 Рік тому +2

    Thanks, much appreciated. Do you use an IOS device?

  • @zoenagy9458
    @zoenagy9458 Рік тому +1

    nextdns at least has debugging tool to find which list blocks domain! love it

  • @ransombaggins9301
    @ransombaggins9301 Рік тому

    My old, deteriorating brain struggled with this one. Was the previous video found be be in error, or does that solution laid out still work as described? I'm just trying to keep things relatively private on my windows laptop, macbook, and iphone. The original video seemed to offer a minimalist solution that made some sense to me. Is that still the case? Thanks for your patience!

  • @Sherin974
    @Sherin974 Рік тому +5

    17:40 People don't use these features so we don't document them and people don't use these features because they aren't documented. Its a cycle. IDK man if I worked couple hundred man hours on a product or service you'd think I'd want to let people to know how to use it.

  • @aryanjohnsharma
    @aryanjohnsharma Рік тому

    Yessss, we need more Videos about cool foss Android apps 📈

  • @chibiichen
    @chibiichen Рік тому

    Is it a privacy issue when I use Androids DOH settings and a vpn? Ipleaks shows me the DNS server of Adguard and Nextdns.

  • @hayrullahtg529
    @hayrullahtg529 Рік тому +1

    Hey, man I'm a new sub and learned a lot quickly, so thanks for the great videos. Could you make a video on how to make a private, secure and anonymous E-mail account network/system? I was trying to research it but there are too many products and I don't know how to build an ecosystem with it, that is why I might need some help, please.

  • @opium4880
    @opium4880 7 місяців тому

    I'm still kind of confused about the set-up. I wanna make sure I'm using it right. Here's my setup:
    System:
    - Apple Configuration Profile on macOS
    - DNS-over-TLS/QUIC on Android
    Browsers:
    - DNS-over-HTTPS on Brave Macbook
    - DNS-over-HTTPS on Brave Mobile
    Mullvad:
    - IPv6 & DNS servers On Macbook
    - IPv6 & DNS servers On Android
    Does this look correct? Is it overkill?

  • @TheDirge69
    @TheDirge69 Рік тому

    excellent presso !

  • @redeyesdrogon786
    @redeyesdrogon786 Рік тому +2

    The documentation is a bit weird when they say they cover something but don't actually do that

  • @RoscoeDaMule
    @RoscoeDaMule Рік тому

    thanks!!

  • @Spiralnebel_GB
    @Spiralnebel_GB Рік тому

    Thanks for breaking down 👍
    Wouldn‘t it be much easier for NextDNS to provide DoH/DoT config profiles for iOS like for example Quad9 offers!? 😂Someone should get in contact with them and suggest this Thus way they could offer the better DoT as well for everyone

  • @RoscoeDaMule
    @RoscoeDaMule Рік тому

    how do you know that next dns is being used after u input the info???? i dont know if its working or not hehe

  • @turbolag5107
    @turbolag5107 Рік тому

    With android, I went into the settings of the device itself and put Next DNS as my private DNS and then ran Proton VPN as normal and went to multiple DNS detecting websites and they all said NextDNS with no DNS leaks.

  • @jacksoncremean1664
    @jacksoncremean1664 Рік тому +1

    4:35 the Linux client is currently in beta so not all features have yet been implemented

  • @zer0r00t
    @zer0r00t Рік тому +1

    I can confirm that private DNS on Android works just fine with windscribe. Did you check if chrome's own DoH is turned off?

  • @McMaxW
    @McMaxW 10 місяців тому

    What about Unbound (using pihole)?

  • @Mojo_DK
    @Mojo_DK Рік тому

    Can you make a video about DNS over Quic?

  • @APT4308
    @APT4308 Рік тому

    Does DoH with VPN reduce “privacy” as people stand out more? Also if you already trust VPN provider with your traffic how is custom DNS improve things?

    • @APT4308
      @APT4308 Рік тому +1

      Ah never mind it was addressed in the video 😂

  • @wildyato3737
    @wildyato3737 6 місяців тому

    Hey so what's the clear difference between DOT and DoH ?..
    I think it was for Android and browser level😂 ..
    TLS/HTTpS aren't same?

  • @naimaustin-se9vh
    @naimaustin-se9vh Рік тому

    Can you do a video on internet protection for game consoles like ps5

  • @tarakivu8861
    @tarakivu8861 Рік тому +1

    Other systems are weird.. on Linux Desktop its just so easy to have such a custom solution.
    Locally host your own DNS and passthrough the rest, no problem.

  • @FirstLast-is9xe
    @FirstLast-is9xe 14 днів тому

    Whats the point of using other DNS than from the VPN provider? I mean, they have all visited IPs anyways.

  • @walid6329
    @walid6329 Рік тому

    Adguard VPN would have solved your problems, btw a review on it would be amazing

  • @gocygo4862
    @gocygo4862 Рік тому +1

    Proton vpn actually does support doh and custom dns on x64 Linux but not arm or x86

  • @brettknoss486
    @brettknoss486 8 місяців тому

    How did you get android to work?

  • @gocygo4862
    @gocygo4862 Рік тому +1

    Doh with ivpn on windows doesn’t work for me

  • @Fan_of_Ado
    @Fan_of_Ado Рік тому

    Can you comment on obfuscation protocols like trojan gfw or v2ray?

    • @Fan_of_Ado
      @Fan_of_Ado Рік тому

      In some places in the world (etc. China) all WireGuard and OpenVPN connections don't work

    • @Fan_of_Ado
      @Fan_of_Ado Рік тому

      Currently self hosting a custom obfuscated protocol based on trojan-gfw but integrated with QUIC

    • @drastically143
      @drastically143 Рік тому

      Thanks for the indirect advice, i sadly too live in the country with censorship.

  • @Mojo_DK
    @Mojo_DK Рік тому

    To know if this works with Safing would be interesting :o

  • @guyfawkes5012
    @guyfawkes5012 Рік тому +2

    Apparently Android DoH + ProtonVPN also works while leaving Netshield on.. at least in my case.

    • @guyfawkes5012
      @guyfawkes5012 Рік тому

      Nvm not after/if you reconnect your VPN.. weird

    • @paulverbeke9212
      @paulverbeke9212 Рік тому

      @@guyfawkes5012 working fine for me

    • @techlore
      @techlore  Рік тому

      Yeah I'm seeing mixed things about whether Netshield needs to be on or off. Again, documenting features would be nice so we don't have to test everything ourselves :P -H

  • @bluorca
    @bluorca Рік тому

    Great, now I have proton and ivpn too! lol

  • @ignoram9us
    @ignoram9us Рік тому

    only the nextdns command line (cli) is open source. nextdns (the resolver) itself isn't.

  • @limon_perplexus
    @limon_perplexus Рік тому

    Hi,
    Could you look into the samsung cloud and Samsung secure folder security?

  • @-someone-.
    @-someone-. Рік тому

    I use NORD and I’ve never been able to use my set piholes as my DNS. Breaks the internet.

  • @dc-k4868
    @dc-k4868 Рік тому +1

    I'm primarily using Android and NextDNS and Torguard and the private DNS route seems to work ok for me.

  • @llllIIIlIll
    @llllIIIlIll Рік тому +1

    Why you never cover torguard

    • @techlore
      @techlore  Рік тому +2

      And why would we? Not open source, no audits, misleading marketing: "Anonymous VPN" - refer to our VPN video on some basic criteria that almost no VPNs hit, including TG: ua-cam.com/video/u-uj_dLXu5s/v-deo.html -H

  • @nicholastoo7543
    @nicholastoo7543 Рік тому

    Next dns, it's just a point of exposure.

  • @keywal
    @keywal Рік тому +1

    Too soon to mention Tailscale? 😅

  • @jjaxs1571
    @jjaxs1571 Рік тому +1

    This is ridiculous. I paid for all 3 services because of your last video. That is because I am a desktop service man so I needed many services. Now I have to cancel the contract and I have a court date with the big one.

  • @benjotest5990
    @benjotest5990 Рік тому

    Wevpn Seem to work 🤔

  • @benjotest5990
    @benjotest5990 Рік тому

    I Think nord also support it 😂😂

  • @DummyFace123
    @DummyFace123 11 місяців тому +1

    Don’t feel bad, documentation of products is bad even when companies are in good faith, not to even mention bad faith marketing..
    For products that just say “works on iOS and android!” but doesn’t say WHAT works on both, it’s like don’t even bother with them.
    If they can spend millions of dollars developing a product, yet more hundreds of thousands of dollars marketing it, and then not take the time to document it, fk em~
    No sympathy. Don’t waste your time doing their jobs for them, let evolution take its course.

  • @frankgregory-xs6nw
    @frankgregory-xs6nw Місяць тому

    Nice lack of apology. Way to be mad at the viewers calling you out, versus being disappointed in yourself.